<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>HP Application Security Center News</title><link>http://www.communities.hp.com/securitysoftware/blogs/products/default.aspx</link><description>News, events, and release information from the Application Security Center product management group.</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><geo:lat>33.926753</geo:lat><geo:long>-84.338776</geo:long><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/SpiProductNews" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>AMP 8.00 Released</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/EeymoKfptUE/amp-8-00-released.aspx</link><pubDate>Fri, 17 Apr 2009 03:42:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89011</guid><dc:creator>jmorgan127</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=89011</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2009/04/17/amp-8-00-released.aspx#comments</comments><description>&lt;p&gt;On Wednesday April 15&lt;sup&gt;th&lt;/sup&gt; we announced a major release of HP Applications Security Center&amp;#39;s Assessment Management Platform.&amp;nbsp; Version 8.00 of the flagship enterprise web application security product brings innovations and feature across the system to enable our customers to:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;u&gt;Establish a web application security Center of Excellence &lt;/u&gt;&lt;/b&gt;&lt;u&gt;which crosses the organization and the application lifecycle&lt;/u&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Leverage and scale the capabilities of you limited security resources and increase security testing coverage of your enterprises web assets by engaging resources outside your core application security team.&lt;/li&gt;
&lt;li&gt;Address application security earlier in the applications lifecycle to reduce rework and risk&lt;/li&gt;
&lt;li&gt;Free up your security specialists to focus on high value target sites and security activities&lt;/li&gt;
&lt;li&gt;Protect sensitive security information and control the use of powerful web application scanning tools through AMP&amp;#39;s central management&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Integrate with IT systems to identify web assets the data that they expose and incorporate web application security into the greater Application Lifecycle and IT processes.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;&lt;u&gt;Build a unified picture of your corporate web application assets and security efforts across the enterprise&lt;/u&gt;&lt;/b&gt;&lt;u&gt; to add business context, improve web application security efforts and make better business decisions.&lt;/u&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Focus on the areas of high risk to the business and identify coverage holes&lt;/li&gt;
&lt;li&gt;Communicate to business management in the context of business needs &lt;/li&gt;
&lt;li&gt;Identify organizational level trends and opportunities &lt;/li&gt;
&lt;li&gt;Track and manage&amp;nbsp;application security process, compliance and&amp;nbsp;vulnerabilities&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;&lt;u&gt;Target Web 2.0 technology with&lt;/u&gt;&lt;/b&gt;&lt;u&gt; best-in-class tools that&lt;/u&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Automatically decompile and statically analyze client-side Rich Internet Applications &lt;/li&gt;
&lt;li&gt;Automatically traverse client-side applications built entirely in JavaScript &lt;/li&gt;
&lt;li&gt;Accurately authenticate to complex web applications &lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Over the next few weeks I will be dedicating blog entries to each of the above areas and how you can use AMP 8.00 to improve and mature your Web Application Security program.&amp;nbsp; The team has done extensive work across the product to support these capabilities, and though we are going to delve deeper into the above areas and the features that support them across the next few weeks, I want to give you a taste of what is in this release.&amp;nbsp; &amp;nbsp;Here is a brief list of what&amp;#39;s new and improved in AMP 8.00.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;u&gt;New in the AMP 8.00&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Tagging / Custom Properties&lt;/b&gt; - Add asset, business, regulatory, project and process information through a flexible name / value pair tagging system to give context to the information and &lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Identify coverage holes and areas of high risk&lt;/li&gt;
&lt;li&gt;Communicate to business management in the context of business needs&lt;/li&gt;
&lt;li&gt;Identify organizational level trends, risks, and opportunities&lt;/li&gt;
&lt;li&gt;Track and manage status and process&lt;/li&gt;&lt;/ul&gt;
&lt;li&gt;
&lt;div&gt;&lt;b&gt;Customizable and Enterprise Reporting &lt;/b&gt;- AMP 8.00 features a new enterprise level reporting system capable of considering data from across the system and rolling that up into enterprise level reports. This highly flexible system gives the customer the ability to create a custom reporting set that is build for their specific organizational and business needs to:&lt;/div&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Generate reports that rollup data to business level entities (ex. Business units, development team, functional area, etc.)&lt;/li&gt;
&lt;li&gt;Track projects across lifecycle and version changes.&lt;/li&gt;
&lt;li&gt;Visualize Trends across scans, sites, organizations, etc.&lt;/li&gt;&lt;/ul&gt;
&lt;li&gt;&lt;b&gt;Scan Monitoring&lt;/b&gt; - View rich, near real time, status information on scans executing on the AMP Sensors. The ability to monitor the scans progress in near real time dramatically simplifies this scenario. Reducing the time and effort required to configure and execute WAS scans. &lt;/li&gt;
&lt;li&gt;&lt;b&gt;Pluggable &amp;quot;Send To&amp;quot; Integration Infrastructure&lt;/b&gt; - The &amp;quot;Send To&amp;quot; infrastructure allows the customer or ASC professional services to quickly build integrations between the AMP system and other key Application Lifecycle and IT systems.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Flash Static Analysis&lt;/b&gt; - AMP Sensors can now decompile Shockwave Flash (SWF) files and then perform static analysis on the resulting ActionScript 3 code, detecting vulnerabilities such as insecure programming practices, insecure application deployment, Adobe &amp;quot;best practices&amp;quot; violations, and information disclosures.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Optional Depth First Crawler&lt;/b&gt; - Depth-first crawling accommodates sites that enforce order-dependent navigation (where you must visit page A before you can visit page B). &lt;/li&gt;
&lt;li&gt;&lt;b&gt;Java Model View Control (MVC) Support&lt;/b&gt;- Based on in-depth research by the HP DevInspect for Java team, AMP Sensors now supports applications built on the Java MVC platform by the use of the Depth First Crawler, Path-based Attacks, and Navigational Parameters.&lt;/li&gt;
&lt;li&gt;more...&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;&lt;u&gt;Improved in AMP 8.00 &lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Enhanced Vulnerability Management and Viewing&lt;/b&gt; - Quickly review, manage and annotate vulnerabilities from within the AMP user interface. Give the extended application security team (including development, QA and lesser skilled technicians) the ability to perform the scan review process without the need of an extensive desktop tool.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Scan Template Generation&lt;/b&gt; -&amp;nbsp; Easily provide a scan template for others stakeholders within the application lifecycle so that they may execute the scans, freeing up the security specialists, to focus on high value target sites and security policies. &lt;/li&gt;
&lt;li&gt;&lt;b&gt;Revamped Web Macro Recorder&lt;/b&gt; - The Web Macro Recorder is now easier to use and incorporates a new algorithm for determining a logout condition. &lt;/li&gt;
&lt;li&gt;&lt;b&gt;Scalability Enhancements&lt;/b&gt; - The fundamental data access and display methodology of the AMP system has been improved to greatly enhance the scalability and responsiveness of the AMP system.&lt;/li&gt;
&lt;li&gt;more...&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;The AMP 8.00 release is &lt;b&gt;available now &lt;/b&gt;to all AMP customers with a current support contract.&amp;nbsp; AMP customers should contact HP technical Support for access to new software online at &lt;b&gt;&lt;a href="http://support.openview.hp.com/"&gt;http://support.openview.hp.com/&lt;/a&gt;&lt;/b&gt; or call&lt;b&gt; 1-800-633-3600&lt;/b&gt;.&amp;nbsp; You will need your SAID and AMP License Token.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;For more information on this release, check out our &lt;/p&gt;
&lt;p&gt;Press release: &lt;b&gt;&lt;a title="http://www.hp.com/hpinfo/newsroom/press/2009/090415xa.html&amp;#10;blocked::http://www.hp.com/hpinfo/newsroom/press/2009/090415xa.html" href="http://www.hp.com/hpinfo/newsroom/press/2009/090415xa.html"&gt;http://www.hp.com/hpinfo/newsroom/press/2009/090415xa.html&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;and&lt;/p&gt;
&lt;p&gt;Launch page:&lt;b&gt; &lt;a href="http://www.hp.com/go/stophackers"&gt;www.hp.com/go/stophackers&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;and &lt;/p&gt;
&lt;p&gt;watch this blog for more to come....&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Jeff Morgan&lt;/p&gt;
&lt;p&gt;Product Manager, HP Assessment Management Platform&lt;br /&gt;HP Application Security Center&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89011" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpiProductNews?a=EeymoKfptUE:13LrhYmHiB8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpiProductNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpiProductNews?a=EeymoKfptUE:13LrhYmHiB8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpiProductNews?i=EeymoKfptUE:13LrhYmHiB8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/EeymoKfptUE" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2009/04/17/amp-8-00-released.aspx</feedburner:origLink></item><item><title>Announcing WebInspect 8.0.548 Available Now!</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/LbYc-zVprd4/announcing-webinspect-8-0-548-available-now.aspx</link><pubDate>Wed, 01 Apr 2009 09:15:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:88709</guid><dc:creator>joe.yeager</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=88709</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2009/04/01/announcing-webinspect-8-0-548-available-now.aspx#comments</comments><description>&lt;p class="SectionTitle"&gt;It is with great pleasure that I announce on behalf of HP Application Security Center, the next leap forward in web security products with the release 
of&amp;nbsp;WebInspect 8.0.&amp;nbsp; With a long list of features, we hope that you are as fired up about this release as we are.&amp;nbsp; Below is just a taste of the many improvements you will enjoy.&lt;/p&gt;&lt;p class="SectionTitle"&gt;&lt;b&gt;What&amp;#39;s New 
&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p class="ListItem"&gt;&lt;b&gt;Flash Static Analysis&lt;/b&gt; - WebInspect can now 
decompile Shockwave Flash (SWF) files and then perform 
static analysis on the resulting ActionScript 3 code, detecting vulnerabilities 
such as insecure programming practices, insecure application deployment, Adobe 
“best practices” violations, and information disclosures.&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p class="ListItem"&gt;&lt;b&gt;New Reporting System&lt;/b&gt; - WebInspect’s new and 
powerful reporting system facilitates the presentation of analyzed data. Now you 
can:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Create reports that are flexible, scalable, and faster using 
an improved generation workflow.
&lt;/li&gt;&lt;li&gt;Modify standard reports or design your own using our new 
report designer.
&lt;/li&gt;&lt;li&gt;Include information from external data sources.
&lt;/li&gt;&lt;li&gt;Customize fonts, colors, and backgrounds with the new style 
editor.
&lt;/li&gt;&lt;li&gt;Generate scan reports with a professional, polished 
appearance.
&lt;/li&gt;&lt;li&gt;Focus analysis on a single session with our new session 
reports.&lt;/li&gt;&lt;/ul&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p class="ListItem"&gt;&lt;b&gt;Optional Depth First Crawler &lt;/b&gt;- Depth-first 
crawling accommodates sites that enforce order-dependent navigation (where you 
must visit page A before you can visit page B). This method traces the first 
link on a page to the first link on the referenced page before returning to the 
original page and tracing the second link. By contrast, breadth-first crawling 
(which is also available) follows all the links on a page before drilling down 
to the pages that are being linked. &lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p class="ListItem"&gt;&lt;b&gt;Java Model View Control (MVC) Support&lt;/b&gt;- Based 
on in-depth research by the HP DevInspect for Java team, WebInspect now supports 
applications built on the Java MVC platform by the use of the Depth First 
Crawler, Path-based Attacks, and Navigational Parameters.&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p class="ListItem"&gt;&lt;b&gt;Integration with IBM Rational ClearQuest &lt;/b&gt;- 
You can now send vulnerabilities as defects directly to IBM Rational ClearQuest 
version 7.&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p class="ListItem"&gt;&lt;b&gt;Support for 64-bit Vista &lt;/b&gt;- You can now run 
WebInspect on 64-bit Vista operating systems.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p class="SectionTitle"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="SectionTitle"&gt;&lt;b&gt;What&amp;#39;s Improved 
&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p class="ListItem"&gt;&lt;b&gt;Significantly Improved Script Processing &lt;/b&gt;- 
WebInspect now handles applications that have heavy client-side JavaScript. As applications 
move to the client, they become a single page that delivers an application 
almost entirely written in JavaScript, making it very difficult for a scanner to 
follow links when crawling the application. Crawling is becoming more about 
following code paths through the JavaScript, analyzing how the application changes 
from the user’s perspective, watching AJAX requests and making attacks to 
the server accordingly. &lt;b&gt;WebInspect 8.0 delivers breakthroughs in 
JavaScript technology &lt;/b&gt;by tracing and recording code paths as 
subsessions, which are then audited to reveal vulnerabilities. &lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p class="ListItem"&gt;&lt;b&gt;Revamped Web Macro Recorder &lt;/b&gt;- The Web Macro 
Recorder is now easier to use and incorporates a new algorithm for determining a 
logout condition. Once you record the login sequence, the Web Macro Recorder 
automatically samples the Web site to discover specific keywords that are 
present when state has been acquired and when it has been lost. This allows the 
scanner to reacquire state if it inadvertently becomes &amp;quot;logged out.&amp;quot; The Web 
Macro Recorder also now allows you to verify that your macros work as expected 
before you use them.&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p class="ListItem"&gt;&lt;b&gt;Smart Assessment Fingerprinting &lt;/b&gt;- WebInspect 
is now more accurate than ever when choosing which checks to use against 
websites.&amp;nbsp; It runs a series of fingerprint requests to determine the server 
type, version, and platforms supported.&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p class="ListItem"&gt;&lt;b&gt;Improvements to Start Page&lt;/b&gt; - The layout, 
appearance, and general usability of the page have been improved. It displays 
new scan attribute columns in the Manage Scans workspace, which improves scan 
selection. You can also group scans by scan attributes. The Activity Panel is 
also collapsible to increase your Manage Scans workspace.&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p class="ListItem"&gt;&lt;b&gt;Improvements to Scan View&lt;/b&gt; - Excluded hosts 
and allowed hosts are distinctly grouped, and the Scan statistics panel has been 
moved to the right of the dashboard for a better look and feel. The Scan 
Dashboard has an improved layout featuring a prominent scan status, crawl and 
audit activity indicators with rolling performance counters, script (JavaScript 
and VBScript) execution indicator, and a listing of attack engines grouped by 
attack type.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;


&lt;p style="font-size:130%;font-weight:bold;"&gt;WebInspect 8.0 is currently LIVE on SmartUpdate! &lt;br /&gt;&lt;/p&gt;

&lt;p&gt;Simply open WebInspect and connect to SmartUpdate, our standard patch channel, and you will automatically receive WebInspect 8.0.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Pre-Requisite Notes:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Requires &lt;a href="http://www.communities.hp.com/securitysoftware/blogs/products/archive/2009/02/24/upgrade-to-net-3-5-service-pack-1.aspx"&gt;.NET Framework 3.5 Service Pack 1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Requires SQL Server 2005 or &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=3181842a-4090-4431-acdd-9a1c832e65a6&amp;amp;displaylang=en"&gt;SQL Server 2005 Express&lt;/a&gt; (free)&lt;/li&gt;&lt;li&gt;Does not support SQL Server 2008 or SQL Server 2008 Express&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;More in the &lt;a href="https://download.spidynamics.com/products/webinspect/webinspectreleasenotes.txt"&gt;release notes&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;Joe Yeager&lt;br /&gt;Product Manager, WebInspect&lt;br /&gt;HP Application Security Center &lt;br /&gt;&lt;br /&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=88709" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpiProductNews?a=LbYc-zVprd4:eF1oT8WX4nM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpiProductNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpiProductNews?a=LbYc-zVprd4:eF1oT8WX4nM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpiProductNews?i=LbYc-zVprd4:eF1oT8WX4nM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/LbYc-zVprd4" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/WebInspect/default.aspx">WebInspect</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/software+update/default.aspx">software update</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/Update/default.aspx">Update</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/release/default.aspx">release</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/new+release/default.aspx">new release</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/what_2700_s+new/default.aspx">what's new</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/Patches/default.aspx">Patches</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/Flash+Security/default.aspx">Flash Security</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2009/04/01/announcing-webinspect-8-0-548-available-now.aspx</feedburner:origLink></item><item><title>Upgrade to .NET 3.5 Service Pack 1</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/g7OSeVrajUI/upgrade-to-net-3-5-service-pack-1.aspx</link><pubDate>Tue, 24 Feb 2009 22:06:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:88060</guid><dc:creator>joe.yeager</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=88060</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2009/02/24/upgrade-to-net-3-5-service-pack-1.aspx#comments</comments><description>&lt;p&gt;Attention all WebInspect, AMP, and QAInspect users,&lt;/p&gt;&lt;p&gt;The next version of WebInspect, QAInspect, and the AMP sensors* will require the .NET Framework 3.5 Service Pack 1.&amp;nbsp; Microsoft has released this version via Windows/Microsoft Update as a
high priority update which means that some of you may already have
it installed.&amp;nbsp; If not, make sure your systems are ready in advance by installing it from either of the following links.&amp;nbsp; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bootstrapper install: &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=ab99342f-5d1a-413d-8319-81da479ab0d7&amp;amp;displaylang=en" title="http://www.microsoft.com/downloads/details.aspx?familyid=ab99342f-5d1a-413d-8319-81da479ab0d7&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=ab99342f-5d1a-413d-8319-81da479ab0d7&amp;amp;displaylang=en&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Full [Direct] download: &lt;a href="http://download.microsoft.com/download/2/0/e/20e90413-712f-438c-988e-fdaa79a8ac3d/dotnetfx35.exe" title="http://download.microsoft.com/download/2/0/e/20e90413-712f-438c-988e-fdaa79a8ac3d/dotnetfx35.exe"&gt;http://download.microsoft.com/download/2/0/e/20e90413-712f-438c-988e-fdaa79a8ac3d/dotnetfx35.exe &lt;/a&gt;&lt;/p&gt;&lt;p&gt;Installing this version will not affect your current installations of WebInspect, AMP, or QAInspect and is highly recommended by our support team as it has many memory and performance improvements. &lt;/p&gt;&lt;p&gt;In anticipation of this question, we cannot provide details as to the timing of the next release of any of these products due to standard HP policies.&lt;/p&gt;&lt;p&gt;* - Only the servers will require the upgrade with their next release.&amp;nbsp;
The next release of the AMP Server will not require the upgrade
initially, but we anticipate that a future versions may so we advise
you to go ahead and upgrade these as well.&amp;nbsp; In doing so, the server
will benefit from the performance and stability improvements mentioned
above. &lt;/p&gt;&lt;p&gt;Cheers,&lt;br /&gt;Joe&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=88060" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpiProductNews?a=g7OSeVrajUI:eOA_0fvQl70:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpiProductNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpiProductNews?a=g7OSeVrajUI:eOA_0fvQl70:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpiProductNews?i=g7OSeVrajUI:eOA_0fvQl70:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/g7OSeVrajUI" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/WebInspect/default.aspx">WebInspect</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/AMP/default.aspx">AMP</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/QAInspect/default.aspx">QAInspect</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/release/default.aspx">release</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/requirements/default.aspx">requirements</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2009/02/24/upgrade-to-net-3-5-service-pack-1.aspx</feedburner:origLink></item><item><title>HP QAInspect 5.1 now available</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/H-QSP4GEdoo/hp-qainspect-5-1-now-available.aspx</link><pubDate>Tue, 14 Oct 2008 23:51:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:86136</guid><dc:creator>patrick.wolf</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=86136</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2008/10/14/hp-qainspect-5-1-now-available.aspx#comments</comments><description>&lt;p&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Introducing HP QAInspect 5.1&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;I am pleased to announce the release of HP QAInspect 5.1 for electronic download and SmartUpdate.&amp;nbsp; QAInspect 5.1 will appear on the HP.com domain for customer and evaluation download within the next few weeks after the system has processed it.&amp;nbsp; This release includes minor cosmetic changes but major changes under-the-covers to improve our integration with Quality Center (in preparation for QC 10) and the latest SecureBase engine.&amp;nbsp; This product was distributed to and tested by several customers in an Early Access Program with great results.&amp;nbsp;&amp;nbsp;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;p&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;What’s New in 5.1&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;Improved User Permissions&lt;/span&gt;&lt;/b&gt;&lt;/font&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="COLOR:#1f497d;"&gt;QAInspect no longer uses the Command Object to &amp;nbsp;communicate with Quality Center.&amp;nbsp; This dramatically reduces the minimum user permissions needed to run a QAInspect test. &amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt; 
&lt;ul&gt;
&lt;li&gt;
&lt;div class="MsoListParagraph" style="MARGIN:0in 0in 0pt 0.5in;TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo1;"&gt;&lt;span style="COLOR:#1f497d;FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;span style="FONT:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;To integrate QAInspect into a Quality Center project requires ”Customize Project Entities” as a minimum access requirement.&amp;nbsp; This is a one-time setting that creates the custom fields necessary in the project.&amp;nbsp; Once it is included in the project any user is able to use QAInspect.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraph" style="MARGIN:0in 0in 0pt 0.5in;TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo1;"&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Quality Center’s default QA Tester user level is now sufficient to configure and run a QAInspect test.&amp;nbsp; This role is also able to fully publish defects found during a security scan.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font face="Calibri" size="3"&gt;Updated Scan Engine&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;QAInspect 5.1 has been updated to include the most recent scanning engine making it compatible with WebInspect 7.7.&amp;nbsp; &amp;nbsp;This includes new tests, performance improvements and greater infrastructure support.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;ul&gt;
&lt;li&gt;&lt;pre style="MARGIN-LEFT:0.5in;TEXT-INDENT:-0.25in;mso-list:l1 level1 lfo2;"&gt;&lt;span style="FONT-SIZE:11pt;COLOR:#1f497d;FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;span style="FONT:7pt &amp;#39;Times New Roman&amp;#39;;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="FONT-SIZE:11pt;COLOR:#1f497d;FONT-FAMILY:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Enhancements to the Cross-Site Scripting (XSS) Engine&lt;/span&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;&lt;pre style="MARGIN-LEFT:0.5in;TEXT-INDENT:-0.25in;mso-list:l1 level1 lfo2;"&gt;&lt;span style="FONT-SIZE:11pt;COLOR:#1f497d;FONT-FAMILY:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;/span&gt;&lt;span style="COLOR:#1f497d;FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;span style="FONT:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Significant SQL Injection Engine Accuracy Improvements&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;&lt;pre style="MARGIN-LEFT:0.5in;TEXT-INDENT:-0.25in;mso-list:l1 level1 lfo2;"&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;/span&gt;&lt;span style="COLOR:#1f497d;FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;span style="FONT:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Enhancements to the JavaScript Parser&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;Automatic Proxy configuration (PAC) support:&lt;/span&gt;&lt;/b&gt;&lt;/font&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;span style="COLOR:#1f497d;"&gt;With the inclusion of the latest scanning engine QAInspect 5.1 also inherits full support for automatic proxy configuration (PAC) files.&amp;nbsp; If your organization utilizes PAC files please test this version to assure that it works in your environment.&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Deactivate License:&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;QAInspect licenses are assigned to specific computers. If you would like to transfer a license from one computer to another, you can now use the Deactivate license feature.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Ready for Download Today:&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Install Files&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt 0.5in;"&gt;&lt;a title="https://download.spidynamics.com/products/qainspect/hp/qainspectqcsetup.exe" href="https://download.spidynamics.com/products/qainspect/hp/qainspectqcsetup.exe"&gt;&lt;font face="Calibri" size="3"&gt;https://download.spidynamics.com/products/qainspect/hp/qainspectqcsetup.exe&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;span style="COLOR:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Documentation&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt 0.5in;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;span style="COLOR:#1f497d;"&gt;Quick Start -&lt;/span&gt; &lt;/font&gt;&lt;/font&gt;&lt;a title="https://download.spidynamics.com/products/qainspect/hp/qainspectqcquickstart.pdf" href="https://download.spidynamics.com/products/qainspect/hp/qainspectqcquickstart.pdf"&gt;&lt;font face="Calibri" size="3"&gt;https://download.spidynamics.com/products/qainspect/hp/qainspectqcquickstart.pdf&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; &lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt 0.5in;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;span style="COLOR:#1f497d;"&gt;User Guide -&lt;/span&gt; &lt;/font&gt;&lt;/font&gt;&lt;a title="https://download.spidynamics.com/products/qainspect/hp/qainspectqcuserguide.pdf" href="https://download.spidynamics.com/products/qainspect/hp/qainspectqcuserguide.pdf"&gt;&lt;font face="Calibri" size="3"&gt;https://download.spidynamics.com/products/qainspect/hp/qainspectqcuserguide.pdf&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; &lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt 0.5in;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;span style="COLOR:#1f497d;"&gt;Release Notes -&lt;/span&gt; &lt;/font&gt;&lt;/font&gt;&lt;a title="https://download.spidynamics.com/products/qainspect/hp/qainspectqcreleasenotes.txt" href="https://download.spidynamics.com/products/qainspect/hp/qainspectqcreleasenotes.txt"&gt;&lt;font face="Calibri" size="3"&gt;https://download.spidynamics.com/products/qainspect/hp/qainspectqcreleasenotes.txt&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=86136" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=gvAfulym"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=KPcLlL6n"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=KPcLlL6n" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/H-QSP4GEdoo" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2008/10/14/hp-qainspect-5-1-now-available.aspx</feedburner:origLink></item><item><title>WebInspect 7.7.869 Now Available</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/v_cuczj2Isg/WebInspect-7.7.869-Now-Available.aspx</link><pubDate>Thu, 12 Jun 2008 11:00:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83144</guid><dc:creator>joe.yeager</dc:creator><slash:comments>5</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=83144</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2008/06/12/WebInspect-7.7.869-Now-Available.aspx#comments</comments><description>&lt;p&gt;An update for WebInspect is now available via SmartUpdate.&amp;nbsp; The update includes some great changes which have been detailed below.&amp;nbsp; Enjoy!&lt;/p&gt;&lt;p&gt;&lt;b&gt;Improvements to the Regular Expression Editor&lt;/b&gt;&lt;br /&gt;Optimized some functions for improved performance (language syntax application, syntax evaluation triggering points, etc).&lt;br /&gt;Disabled match tree updates on match fill. Refactored control that contains text to test and disabled painting while highlighting. Improved test for validity of request/response templates. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Enhancements to the Cross-Site Scripting (XSS) Engine&lt;/b&gt;&lt;br /&gt;Improved detection of Cross-Site Scripting vulnerabilities and improved consistency in stored Cross-Site Scripting detection. Improved accuracy of Cross-Site Scripting against Domino HTTP headers, as well as when filters are used to remove &amp;quot;alert&amp;quot; from the query string, in Header Injection, and in chain drop-down sites. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Significant SQL Injection Engine Improvements&lt;/b&gt;&lt;br /&gt;Improved &amp;quot;diffing&amp;quot; technology for blind SQL Injection. Implemented data extraction for proving confirmed SQL Injection. Improved vulnerability categorization, and created a new check that is flagged when SQL Injection is confirmed but data extraction is not possible because of some limitations such as database not supported, database version does not support data extraction, et cetera.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Enhancements to the JavaScript Parser&lt;/b&gt;&lt;br /&gt;Fixed a recurring error when parsing script out-of-process and enhanced the detection of forms in JavaScript so that more forms are found.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Improved Results for Web Brute&lt;/b&gt;&lt;br /&gt;Integrated DiffEngine changes into Web Brute for improved results.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Stability Enhancements&lt;/b&gt;&lt;br /&gt;Significant work was put towards closing a large number of outstanding issues.&amp;nbsp; See the &lt;a href="https://download.spidynamics.com/products/webinspect/webinspectreleasenotes.pdf"&gt;release notes&lt;/a&gt; for more details.  &lt;/p&gt;&lt;p&gt;&lt;b&gt;Miscellaneous Improvements&lt;/b&gt;&lt;br /&gt;Additional enhancements include better handling of Proxy PAC files, Firefox Proxy support, and improved Oracle application support.&amp;nbsp; Additionally, the &amp;quot;Manage Existing Scans&amp;quot; dialog now remembers its window size and position.&amp;nbsp;&lt;/p&gt;&lt;p&gt;For additional details and a full list of issues resolved, check out the &lt;a href="https://download.spidynamics.com/products/webinspect/webinspectreleasenotes.pdf"&gt;release notes&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;- Joe &lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=83144" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=JnEsFWtC"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=RNOXKcRb"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=RNOXKcRb" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/v_cuczj2Isg" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/WebInspect/default.aspx">WebInspect</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/software+update/default.aspx">software update</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/Service+Pack/default.aspx">Service Pack</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/Update/default.aspx">Update</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/release/default.aspx">release</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/new+release/default.aspx">new release</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/Patches/default.aspx">Patches</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2008/06/12/WebInspect-7.7.869-Now-Available.aspx</feedburner:origLink></item><item><title>DevInspect 5.0 is now available.</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/8tofAomYolk/DevInspect-5.0-is-now-available_2E00_.aspx</link><pubDate>Tue, 01 Apr 2008 00:09:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75792</guid><dc:creator>patrick.wolf</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=75792</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2008/04/01/DevInspect-5.0-is-now-available_2E00_.aspx#comments</comments><description>&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Introducing HP DevInspect 5.0&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect extends the reach of HP&amp;rsquo;s Application Lifecycle Optimization portfolio into product development.&amp;nbsp; Combining our award-winning dynamic application scanning technology with static code analysis, HP DevInspect is the only tool available that performs true Hybrid Analysis &amp;ndash; both white-box and black-box testing.&amp;nbsp; HP DevInspect is seamlessly integrated with the Integrated Development Environment (IDE) &amp;ndash; Visual Studio for .NET or Eclipse or RAD for Java &amp;ndash; minimizing the training required to learn a new tool and eliminating any disruption of the development timeline.&amp;nbsp; The release of HP DevInspect 5.0 further enhances Hybrid Analysis and increases development efficiencies with the following features:&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Visual Studio 2008 Support&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect &amp;nbsp;for .Net now supports Microsoft Visual Studio 2008 and Visual Studio 2005.&amp;nbsp; Businesses can now test for vulnerabilities with Hybrid Analysis regardless of the Visual Studio IDE preferred by their developers even in mixed environments.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Struts 1.x MVC support&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Struts is one of the most popular java frameworks used for web application development. HP DevInspect for Java 5.0 fully supports integrated security testing within Eclipse or IBM RAD for applications using the Struts framework.&amp;nbsp; Corporations using industry standard design practices can now take full advantage of the Hybrid Analysis inherent in HP DevInspect.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Hybrid Analysis&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect is the only product to combine static analysis of all byte-code (both Java and MSIL) with dynamic black-box vulnerability scanning in one.&amp;nbsp; The static &amp;nbsp;analysis and dynamic scan engines have both been upgraded in HP DevInspect 5.0 to increase the accuracy, performance, and repeatability of our Hybrid Analysis. The time and money spent finding and fixing security vulnerabilities can now be dramatically decreased by equipping developers with an IDE with built-in Hybrid Analysis.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Vista Support&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect for Java and HP DevInspect for .Net are now fully supported on Microsoft Vista.&amp;nbsp; IT organizations looking to upgrade their existing desktop environments can transition their developers without risking their ability to perform Hybrid Analysis on their applications. &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^9564_4000_100__" title="DevInspect Home Page"&gt;Ready for Download today!&lt;/a&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=75792" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=rpi6zuqH"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=wxLPvypZ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=wxLPvypZ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/8tofAomYolk" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/DevInspect/default.aspx">DevInspect</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2008/04/01/DevInspect-5.0-is-now-available_2E00_.aspx</feedburner:origLink></item><item><title>QAInspect 5.0 is now available.</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/7AkQEHQTkSs/QAInspect-5.0-is-now-available_2E00_.aspx</link><pubDate>Mon, 31 Mar 2008 16:02:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75778</guid><dc:creator>patrick.wolf</dc:creator><slash:comments>3</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=75778</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2008/03/31/QAInspect-5.0-is-now-available_2E00_.aspx#comments</comments><description>&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Introducing HP QAInspect 5.0&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP QAInspect completes the third pillar of Application Lifecycle Optimization.&amp;nbsp; Does it work?&amp;nbsp; Does it perform?&amp;nbsp; Is it secure?&amp;nbsp; Built on the foundation of the award-winning application scanning technology in HP WebInspect, QAInspect enables quality professionals to fully manage the process of finding and fixing security defects early in the application lifecycle. This ability to manage security defect testing early in the application lifecycle mitigates risk in the application, saves money on revisions over the life of the application, and produces more holistic data &amp;nbsp;for a Go/No Go decision.&amp;nbsp; The upcoming release of HP QAInspect 5.0 extends the already robust integration with Quality Center with the following new features:&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Defect Staging&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;New in QAInspect 5,0 is a staging area to vet vulnerabilities before they are added to the defect table within QC.&amp;nbsp; Users can fully test and validate all vulnerabilities found by the scan to ensure that application developers are only spending development cycles fixing confirmed defects.&amp;nbsp; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Defect Consolidation&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Vulnerabilities found during a scan can now be viewed as a consolidated list, grouped by application page or defect type.&amp;nbsp; For example, a user may view all vulnerabilities found on the login page of an application.&amp;nbsp; Similarly, a user may view all Cross-Site Scripting vulnerabilities or all SQL Injection vulnerabilities grouped into a single pane.&amp;nbsp; The ability to group vulnerabilities allows users to more quickly log specific defects and assign defect tasks to developers with greater accuracy.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Folder Restrictions&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Restrict the crawl and audit of a scan to a particular folder. This allows much more granular control of the testing allowing for better targeted security testing. Once a particular application section has been audited and all security issues mitigated to an acceptible degree it can be moved to regression; focusing new security testing and fixes on new functional areas of the application.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Parameter Highlighting&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;As the size and complexity of web application pages grow the ability to quickly find a specific parameter within a vulnerable page becomes a greater burden.&amp;nbsp; In order to eliminate the time wasted by developers searching a page for a particular vulnerability all defect reports now highlight the specific vulnerable parameter within the HTTP Request/Response pair.&amp;nbsp; Developers can easily find the vulnerable part of the application and apply a fix with limited downtime.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^9561_4000_100__" title="QAInspect Home Page"&gt;Trial License Now Available (Click Here)&lt;/a&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;This release includes a trial license allowing Quality Center customers to download and evaluate QAInspect for 15 days; enabling them to make better purchase decisions.&amp;nbsp; Talk to your sales representative for more details.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=75778" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=HekCjCUQ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=RrhUnbpJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=RrhUnbpJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/7AkQEHQTkSs" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2008/03/31/QAInspect-5.0-is-now-available_2E00_.aspx</feedburner:origLink></item><item><title>New HP Application Security Resource Library</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/9jhLA8km-uI/New-HP-Application-Security-Resource-Library.aspx</link><pubDate>Fri, 11 Jan 2008 16:43:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:73200</guid><dc:creator>erik.peterson</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=73200</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2008/01/11/New-HP-Application-Security-Resource-Library.aspx#comments</comments><description>&lt;p&gt;Hi everyone, we have just completed the new &lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^14344_4000_100__" target="_blank"&gt;HP Application Security Resource Library&lt;/a&gt;. Your one stop shop for product datasheets, whitepapers and presentations. If you currently going to the &lt;a href="http://portal.spidynamics.com/files/default.aspx"&gt;downloads&lt;/a&gt; section on the Portal site for some of this information please update your links and use this new location instead.&lt;/p&gt;&lt;p&gt;If you haven&amp;#39;t had the chance to read some of our whitepapers or presentations, take a moment to check it out, there are great articles on dealing with AJAX security issues, PCI Compliance as well as papers on SQL Injection and Cross Site Scripting (XSS). All together the new HP Application Security Resource Library might be one of the largest collections of application security focused documents available on the web.&lt;/p&gt;&lt;p&gt;We are also always looking for requests on what papers and articles you would like to see added, drop us a comment or two with your requests.&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Erik&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=73200" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=7EoR5dF0"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=hgGCX3gl"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=hgGCX3gl" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/9jhLA8km-uI" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/Application+Security+Resource+Library/default.aspx">Application Security Resource Library</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/whitepapers/default.aspx">whitepapers</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/datasheets/default.aspx">datasheets</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/presentations/default.aspx">presentations</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2008/01/11/New-HP-Application-Security-Resource-Library.aspx</feedburner:origLink></item><item><title>WebInspect 7.7 just around the corner</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/Nlyf9c0HDdg/WebInspect-7.7-just-around-the-corner.aspx</link><pubDate>Fri, 05 Oct 2007 08:58:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:70009</guid><dc:creator>erik.peterson</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=70009</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/10/05/WebInspect-7.7-just-around-the-corner.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;&lt;font size="4"&gt;WebInspect 7.7 coming soon, so what&amp;#39;s new? Great question!&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;What better way to let our customers know that HP is 100% commited to improving and delivering new functionality in WebInspect than to bring everyone a new release. This is our second WebInspect product update since getting aquired and there is a lot of things in this release that I think is going to make&amp;nbsp;everyone very happy.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font size="3"&gt;What&amp;#39;s New&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Re-branding to HP&lt;br /&gt;&lt;/strong&gt;WebInspect has been re-branded to show that it is now a part of the HP Software family. I had the task to pick from all sorts of images to find the one for the splash screen, i&amp;#39;m not sure I found the right one so I plan on changing it in the next release. I&amp;#39;d like to give the WebInspect community the oppertunity to suggest what we put in there next release so drop me a comment with your ideas.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Reports&lt;br /&gt;&lt;/strong&gt;A new False Positive report provides a list of the vulnerabilities that are currently marked as false positive. See &amp;ldquo;Improved False Positive Handling&amp;rdquo; below for more information. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Compliance Updates&lt;/strong&gt;&lt;br /&gt;Two new compliance templates will generate compliance reports based on OMB and OWASP Top 10 2007 requirements. The OMB template addresses major application security sections that were defined in December 2004 by the Office of Management and Budget (OMB) for Federal agency public websites. While the previous OWASP Top 10 list included a mix of vulnerabilities and attacks, the OWASP Top 10 2007 list focuses on vulnerabilities.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;False Positive View&lt;br /&gt;&lt;/strong&gt;WebInspect now has a False Positive view that allows you to see the vulnerabilities and sessions that are currently marked as false positive. From the False Positive view, you can select a session or a vulnerability that you have determined is not a false positive and mark it as a vulnerability again. See &amp;ldquo;Improved False Positive Handling&amp;rdquo; below for more information.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Vulnerability Filtering&lt;br /&gt;&lt;/strong&gt;You can now filter vulnerabilities to prevent multiple parameters for the same session or multiple values sent for the same parameter from appearing multiple times in the site tree and reports. Vulnerability filtering consolidates the related vulnerabilities into a single vulnerability. The Vulnerability Filter is disabled by default, but can be configured on the Settings window under Audit Settings. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Enhanced Web Services Scans&lt;br /&gt;&lt;/strong&gt;WebInspect now supports the use of log-in scripts and a means of specifying parameter values for web services scans. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;font size="3"&gt;What&amp;rsquo;s Improved&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;div&gt;&lt;strong&gt;Improved IPv6 Scanning&lt;br /&gt;&lt;/strong&gt;WebInspect now has improved recognition of IPv6 literal URLs and improved scanning of IPv6 sites. You can type an IPv6 literal URL into the scan wizard and WebInspect will validate the entry, parse the URL, and recognize IPv6 literal addresses in links on web pages. Additionally, Web Discovery handles IPv6 endpoints and range enumeration. &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;&lt;strong&gt;Improved SOAP Assessment&lt;br /&gt;&lt;/strong&gt;WebInspect can now assess web sites that use SOAP Version 1.2 to transmit SOAP messages. SOAP Editor modifications have been made to collect SOAP message values for WSDL scans. Additionally, several known issues involving the SOAP Editor and SOAP assessments have been resolved to generally improve overall SOAP assessments. &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Improved Status Communication to AMP&lt;br /&gt;&lt;/strong&gt;The WebInspect sensor now sends regular status updates to AMP. The updates are displayed as &amp;quot;Scanning X of Y; Duration:00:00:00:0000; Errors:0&amp;quot; in the Devices &amp;agrave; Sensors view on the AMP Console. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Improved False Positive Handling&lt;br /&gt;&lt;/strong&gt;In the Vulnerabilities tab, you can select a session or a vulnerability that you believe to be false positive and send an immediate notification to HP support. If a vulnerability is selected, a list of all URLs that are vulnerable appear in the Mark as False Positive window. You can select all URLs or individual URLs to mark as false positive. You can also type a comment to send to HP support along with your false positive notification.&amp;nbsp; I want to stress how cool this feature is because we have built a portal here at SPI/HP that we log into and can review this stuff. The reports you are sending us are being read by our SPI labs team to help guide the improvements and check changes they make on a daily basis. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Improved Support Channel Communication&lt;br /&gt;&lt;/strong&gt;After submitting a false positive notification to HP support, you will receive a pop-up message from SPI Monitor that includes a tracking number for the notification being sent. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;That&amp;#39;s it! We hope you enjoy it when it&amp;#39;s released, look for it on SmartUpdate on the usual download locations sometime next week.&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=70009" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=EZDgi8nF"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=Mx6cRDXG"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=Mx6cRDXG" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/Nlyf9c0HDdg" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/WebInspect/default.aspx">WebInspect</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/new+release/default.aspx">new release</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/what_2700_s+new/default.aspx">what's new</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/10/05/WebInspect-7.7-just-around-the-corner.aspx</feedburner:origLink></item><item><title>WebInspect Update planned this week</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/XSDXGB0Syw8/WebInspect-Update-planned-this-week.aspx</link><pubDate>Sun, 12 Aug 2007 19:55:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:68475</guid><dc:creator>erik.peterson</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=68475</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/08/12/WebInspect-Update-planned-this-week.aspx#comments</comments><description>&lt;p&gt;Quick update, there will be a minor update for all WebInspect users this week. Mainly lots of little fixes (like the broken SQL Injector start menu link, oops!) but one new feature: Deactivate License. &lt;/p&gt;&lt;p&gt;Ever since we introduced our new licensing system we have made it way too hard to move your copy of WebInspect from one machine to another requiring you to call our support guys if you wanted to move the license. The new deactivate license feature (found under application settings-&amp;gt;license) allows you to deactivate your install (returning WebInspect to a unlicensed state) which then frees up your license to be used again wherever you want. Just use the same activation token you received from us when you bought WebInspect to reactivate your new installation.&lt;/p&gt;&lt;p&gt;For those of you who move your copy of WebInspect around a lot, this should be really handy. Just remember to deactivate before you re-image that machine and you can re-use the activation token again later.&lt;/p&gt;&lt;p&gt;If you have any questions, please post them here and I&amp;#39;ll be quick to answer, thanks!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=68475" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=GEa9y4cR"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=gY4ydZIN"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=gY4ydZIN" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/XSDXGB0Syw8" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/WebInspect/default.aspx">WebInspect</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/deactivate/default.aspx">deactivate</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/License/default.aspx">License</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/08/12/WebInspect-Update-planned-this-week.aspx</feedburner:origLink></item><item><title>QAInspect 4.0.1 for HP Quality Center is now available!</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/jNkzFwDhwHM/QAInspect-4.01-for-HP-Quality-Center-is-now-available_2100_.aspx</link><pubDate>Mon, 06 Aug 2007 10:27:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:68327</guid><dc:creator>erik.peterson</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=68327</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/08/06/QAInspect-4.01-for-HP-Quality-Center-is-now-available_2100_.aspx#comments</comments><description>&lt;p&gt;Hot on the heels of WebInspect 7.5 is HP QAInspect 4.0.1 for HP Quality Center (say that 5 times fast!)&lt;/p&gt;&lt;p&gt;New features include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;div class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font face="Calibri" size="3"&gt;Quality Center 9.2 support&lt;/font&gt;&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font face="Calibri" size="3"&gt;Crawl-Only feature&lt;/font&gt;&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font face="Calibri" size="3"&gt;Windows Authentication for AMP&lt;/font&gt;&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font face="Calibri" size="3"&gt;Ability to update license through a proxy&lt;/font&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Contact your support represenatitive or our sales team today for more information. If you are an existing customer run SmartUpdate now to get the latest updates.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=68327" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=etcKGYFl"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=KbOgNE06"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=KbOgNE06" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/jNkzFwDhwHM" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/QAInspect/default.aspx">QAInspect</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/release/default.aspx">release</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/hp/default.aspx">hp</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/08/06/QAInspect-4.01-for-HP-Quality-Center-is-now-available_2100_.aspx</feedburner:origLink></item><item><title>WebInspect 7.5 now available!</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/T7IzdAHyYk8/WebInspect-7.5-now-available_2100_.aspx</link><pubDate>Thu, 26 Jul 2007 09:55:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:67985</guid><dc:creator>erik.peterson</dc:creator><slash:comments>4</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=67985</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/07/26/WebInspect-7.5-now-available_2100_.aspx#comments</comments><description>&lt;p&gt;Download now from &lt;a href="https://download.spidynamics.com/products/WebInspect/"&gt;https://download.spidynamics.com/products/WebInspect/&lt;/a&gt; or use SmartUpdate.&lt;/p&gt;&lt;p&gt;&lt;span class="style29"&gt;&lt;strong&gt;What&amp;#39;s New&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Pre-scan Profiler&lt;/strong&gt; &amp;ndash; WebInspect&amp;#39;s new pre-scan Profiler analyzes the application and offers suggestions for changes to the scan settings to optimize your assessment. The Profiler can evaluate and recommend settings for authentication, proxies, files not found, allowed hosts, and much more. &lt;br /&gt;The Profiler can be launched as a separate tool or configured in the Scan Wizard to automatically launch prior to the start of a scan. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Interactive Logout Notification&lt;/strong&gt; &amp;ndash; During an interactive mode scan, WebInspect notifies you when a logout has occurred, and displays a browser view of the page where the logout occurred, allowing you to login again. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Traffic Monitor&lt;/strong&gt; &amp;ndash; The Traffic Monitor allows you to view HTTP traffic in real time during a scan. The Traffic Monitor displays every request sent and response received by WebInspect in real time during the crawl and audit.&amp;nbsp; &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Enterprise Assessment&lt;/strong&gt; &amp;ndash; Enterprise Assessment provides you with a comprehensive overview of your Web presence from an enterprise network perspective. URLs and IP addresses can be entered individually, or WebInspect can discover all available servers within a range of IP addresses and ports that you specify. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Right-click SQL Injector&lt;/strong&gt; &amp;ndash; You can now launch the SQL Injector tool by right-clicking on a vulnerable session and selecting SQL Injector from the Tools menu. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Regex in Allowed Hosts&lt;/strong&gt; &amp;ndash; You can now use Regex in the Allowed Hosts list, so that if a host matches a Regex pattern entered, it will be allowed for crawl and audit. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Launch Interactive Mode from Web Macro Recorder&lt;/strong&gt; &amp;ndash; You can now configure the Web Macro Recorder to launch Interactive Mode as part of a Macro. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Restore Factory Defaults to Application Settings&lt;/strong&gt; &amp;ndash; You can now restore Application Settings to their factory default settings. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Launch SPI Proxy from WebInspect Scan Wizard&lt;/strong&gt; &amp;ndash; You can now launch SPI Proxy from the Configure Network Proxy window in the Web Site Assessment wizard. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Windows Vista Support&lt;/strong&gt; - WebInspect 7.5 is now fully supported under windows Vista (Please note, support for 64 bit systems is still forthcoming)&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="SectionTitle"&gt;&lt;strong&gt;What&amp;#39;s Improved&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;AJAX Auditing&lt;/strong&gt; &amp;ndash; AJAX Web applications can create several opportunities for possible attack if the application is not designed with security in mind. Since AJAX Web applications exist on both the client and the server, they include the following security issues:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Create a larger attack surface with many more inputs to secure&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Expose internal functions of the Web application server&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Allow a client-side script to access third-party resources with no built-in security mechanisms&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="ListItem"&gt;Improved AJAX auditing detects common AJAX frameworks that involve the following:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Function calls made in a client-side scripting language, such as JavaScript&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Use of the XMLHttpRequest objects to make data requests without having to reload the page&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Use of JavaScript Object Notation (JSON) format to transfer data between the server and client&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Export Ability in Log Viewer&lt;/strong&gt; &amp;ndash; You can now export Audit, Crawl, Scanner, and StateRequestor logs from the Log Viewer tool. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Manage Scans Enhancement&lt;/strong&gt; &amp;ndash; You can now select and delete multiple scans in the Manage Scans window. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Export Scan Details Enhancement&lt;/strong&gt; &amp;ndash; The Export Scan Details window has been redesigned for improved usability. &lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=67985" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=NUxykz2j"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=aEFzgswI"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=aEFzgswI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/T7IzdAHyYk8" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/WebInspect/default.aspx">WebInspect</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/release/default.aspx">release</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/07/26/WebInspect-7.5-now-available_2100_.aspx</feedburner:origLink></item><item><title>WebInspect 7.1 Now Available</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/LTHqqE0_5Lo/WebInspect-7.1-Now-Available.aspx</link><pubDate>Tue, 22 May 2007 15:21:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:29809</guid><dc:creator>erik.peterson</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=29809</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/05/22/WebInspect-7.1-Now-Available.aspx#comments</comments><description>&lt;div align="center"&gt;&lt;table cellpadding="0" cellspacing="0" class="MsoNormalTable" style="width:487.5pt;"&gt;&lt;tr&gt;&lt;td style="width:609px;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="style1" style="background:#e5e4e0;width:609px;border:#e2e2e2;padding:0in;"&gt;&lt;table cellpadding="0" cellspacing="0" class="MsoNormalTable" style="width:255pt;"&gt;&lt;tr&gt;&lt;td style="width:336px;background-color:transparent;border:#ffffff;padding:5.25pt;"&gt;&lt;p class="style2"&gt;&lt;span class="style5"&gt;&lt;span style="font-size:18pt;font-family:'Arial','sans-serif';"&gt;Now Available&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:18pt;font-family:'Arial','sans-serif';"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;&lt;img border="0" height="65" id="_x0000_i1026" src="http://content3.rm04.net/ra/2007/05/22/869066/CONT_32.jpg" width="250" /&gt;&lt;br /&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;The Next Generation of Web Application Scanning&lt;/span&gt;&lt;/strong&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt; &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height:56.25pt;"&gt;&lt;td style="width:609px;height:56.25pt;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&lt;table cellpadding="0" cellspacing="0" class="style3" style="width:487.5pt;"&gt;&lt;tr&gt;&lt;td class="style1" rowspan="2" style="width:242pt;background-color:transparent;border:#e2e2e2;padding:5.25pt;"&gt;&lt;p&gt;&lt;font size="3"&gt;&lt;strong&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;WebInspect 7.1 features Server Analyzer, a new advanced tool for pen-testers:&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt; &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Server Analyzer is a web server identification and discovery tool designed to quickly identify and understand the nature of&amp;nbsp; a web server or web-enabled device.&lt;/span&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;&amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Identifies popular web server software, web application software, embedded/web-enabled devices, and supporting network architecture components such as proxies and load balancers.&amp;nbsp; &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Uses a special characteristic-based identification technology that is capable of deducing the server software type despite attempts to hide the server software&amp;#39;s true identity. &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Improves server identification accuracy reduces false-positive identifications due to configuration obfuscation. &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Performs deep SSL SSL analysis on HTTPS sites, showing various information related to the server&amp;#39;s SSL configuration.&lt;/span&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt; &lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;td style="background-color:transparent;border:#e2e2e2;padding:5.25pt;"&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;a name="httpwww.spidynamics.comassetsdocumentsWe" title="httpwww.spidynamics.comassetsdocumentsWe"&gt;&lt;/a&gt;&lt;a href="http://www.spidynamics.com/assets/documents/WebInspect_DataSheets.pdf"&gt;&lt;span style="font-family:'Arial','sans-serif';text-decoration:none;text-underline:none;"&gt;&lt;font size="3"&gt;&lt;img border="0" height="108" id="_x0000_i1028" src="http://content3.rm04.net/ra/2007/05/22/869066/CONT_34.jpg" style="float:left;" width="144" /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="background-color:transparent;border:#e2e2e2;padding:5.25pt;"&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;a name="Free_15-day_Trial" title="Free_15-day_Trial"&gt;&lt;/a&gt;&lt;a href="https://download.spidynamics.com/1/ad/fwi.asp?Campaign_ID=70160000000Cq9A"&gt;&lt;span style="font-family:'Arial','sans-serif';text-decoration:none;text-underline:none;"&gt;&lt;font size="3"&gt;&lt;img border="0" height="108" id="_x0000_i1029" src="http://content3.rm04.net/ra/2007/05/22/869066/CONT_35.jpg" style="float:left;" width="144" /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="width:609px;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&lt;table cellpadding="0" cellspacing="0" class="MsoNormalTable" style="width:487.5pt;"&gt;&lt;tr style="height:140.25pt;"&gt;&lt;td class="style1" style="width:331px;height:140.25pt;background-color:transparent;border:#e2e2e2;padding:5.25pt;"&gt;&lt;p&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;The following additional WebInspect 7.1 enhancements were designed to further simplify and speed up the installation and assessment processes. &lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;New simple scan enabling users to conduct a comprehensive scan by entering only the URL, user name and password. &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Faster scans through redundant page detection. &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Simplified installation process by removing the dependency on SQL Server Express. &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Enhanced Quality Center integration.&amp;nbsp; Send defects directly to QC from WebInspect&amp;#39;s site tree or vulnerability pane.&lt;/span&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt; &lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="width:609px;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&lt;p class="style4"&gt;&lt;strong&gt;Already a Customer?&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="width:609px;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&lt;table cellpadding="0" cellspacing="0" class="MsoNormalTable" style="width:487.5pt;"&gt;&lt;tr&gt;&lt;td class="style1" style="width:224pt;background-color:transparent;border:#e2e2e2;padding:3.75pt;"&gt;&lt;p&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;If you are already a WebInspect 7.0 customer and need to upgrade, please run WebInspect and click on the SmartUpdate icon at the bottom of your screen. &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;If you would like to download the installer, please click &lt;/span&gt;&lt;a name="httpsdownload.spidynamics.comproductsweb" title="httpsdownload.spidynamics.comproductsweb"&gt;&lt;/a&gt;&lt;a href="https://download.spidynamics.com/products/webinspect/"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;. &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="width:212pt;background-color:transparent;border:#e2e2e2;padding:3.75pt;"&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;&lt;img border="0" height="108" id="_x0000_i1031" src="http://content3.rm04.net/ra/2007/05/22/869066/CONT_37.jpg" style="float:left;" width="144" /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="width:609px;height:102px;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&lt;p class="style2"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;&lt;font size="3"&gt;&lt;img border="0" height="28" id="_x0000_i1032" src="http://content3.rm04.net/ra/2007/05/22/869066/CONT_38.jpg" width="100" /&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Join the SPI Community &lt;br /&gt;&lt;/span&gt;&lt;a name="httpportal.spidynamics.comblogsdefault.a" title="httpportal.spidynamics.comblogsdefault.a"&gt;&lt;/a&gt;&lt;a href="http://portal.spidynamics.com/blogs/default.aspx"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Blogs&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;, &lt;/span&gt;&lt;a name="httpportal.spidynamics.comforumsdefault." title="httpportal.spidynamics.comforumsdefault."&gt;&lt;/a&gt;&lt;a href="http://portal.spidynamics.com/forums/default.aspx"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Forums&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;, &lt;/span&gt;&lt;a name="httpportal.spidynamics.comfilesdefault.a" title="httpportal.spidynamics.comfilesdefault.a"&gt;&lt;/a&gt;&lt;a href="http://portal.spidynamics.com/files/default.aspx"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Downloads&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt; and &lt;/span&gt;&lt;a name="httpportal.spidynamics.com(3)" title="httpportal.spidynamics.com(3)"&gt;&lt;/a&gt;&lt;a href="http://portal.spidynamics.com/"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;more&lt;/span&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=29809" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=SiWrri7U"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=Jj3EQUhG"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=Jj3EQUhG" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/LTHqqE0_5Lo" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/WebInspect/default.aspx">WebInspect</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/05/22/WebInspect-7.1-Now-Available.aspx</feedburner:origLink></item><item><title>DevInspect for Java SP1 (version 3.0.1.0) now available</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/7x66ynqA8eY/DevInspect-for-Java-SP1-_2800_version-3.0.1.0_2900_-now-available.aspx</link><pubDate>Tue, 03 Apr 2007 14:50:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:28113</guid><dc:creator>erik.peterson</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=28113</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/04/03/DevInspect-for-Java-SP1-_2800_version-3.0.1.0_2900_-now-available.aspx#comments</comments><description>We released last Friday (3/30/07) a service pack to DevInspect for Java to fix some critical installation issues that were causing customers a lot of pains in their installation process when trying to evaluate the Java product. They were minor issues, but were popping up a lot, so we decided we needed to get them fixed as soon as possible to smooth the evaluation process. We also included a new and improved QuickStart guide with more detailed instructions on getting started. The getting started information is also available as an Eclipse &amp;ldquo;cheat sheet&amp;rdquo; within the software, so users will see a guided tutorial that helps them get licenses and scanning after installation.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This version of the DevInspect for Java product is 3.0.1.0, but is functionally identical to the 3.0.0 version. The DevInspect 3.0.1.0 for Java version contains the following:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Fixed an issue with the DevInspect 3.0.0 installation package that in some instances failed to recognize that the required Windows Installer version was present on the installation target.&lt;/li&gt;&lt;li&gt;Fixed an issue with the DevInspect 3.0.0 installation package that failed to recognize that the .NET Framework 2.0 was present when .NET Framework 3.0 had been installed.&lt;/li&gt;&lt;li&gt;Enhancements to the QuickStart and User Guide documentation to help users get started with configuring and using DevInspect.&lt;/li&gt;&lt;li&gt;Introduction of an Eclipse &amp;ldquo;cheat sheet&amp;rdquo; that walks the user through the steps to get started with DevInspect. The cheat sheet will appear upon initial startup of the standalone version of DevInspect. In other versions, or after closing the cheat sheet, you can open it by opening Window&amp;hellip;Show View&amp;hellip;Other and selecting the Cheat Sheets view.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Since these items are in response to installation and ease-of-use issues, if a customer is up and running, they do not need to pick up this service pack. For those that need the service pack to address installer issues, it is distributed in two ways:&lt;br /&gt;&lt;br /&gt;A new installation program is available at: &lt;a href="https://download.spidynamics.com/products/DevInspect/Java/DevInspectJavaSetup.exe"&gt;https://download.spidynamics.com/products/DevInspect/Java/DevInspectJavaSetup.exe&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Existing users can update to this version through the Eclipse Update Manager. To check for DevInspect feature updates, or if you have received notification from SPI Dynamics that a new release is available, follow these steps. Go to Help&amp;hellip;Software Updates&amp;hellip;Manage Configuration. In the Product Configuration dialog, locate and select DevInspect for Java. In the right-hand pane, select Scan for Updates. If updates are found, follow the on-screen instructions to upgrade to the latest version of DevInspect.&lt;br /&gt;&lt;br /&gt;Finally, for those that just need the new and improved QuickStart information, you can get that document here: &lt;a href="https://download.spidynamics.com/products/DevInspect/Java/DevInspectJavaQuickStart.pdf"&gt;https://download.spidynamics.com/products/DevInspect/Java/DevInspectJavaQuickStart.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=28113" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=oGGJKRj1"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=8e2dTqoV"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=8e2dTqoV" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/7x66ynqA8eY" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/DevInspect/default.aspx">DevInspect</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/Service+Pack/default.aspx">Service Pack</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/Java/default.aspx">Java</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/Update/default.aspx">Update</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/04/03/DevInspect-for-Java-SP1-_2800_version-3.0.1.0_2900_-now-available.aspx</feedburner:origLink></item><item><title>WebInspect Update now Available</title><link>http://feedproxy.google.com/~r/SpiProductNews/~3/A5A8663RrzA/WebInspect-Update-now-Available.aspx</link><pubDate>Sat, 17 Mar 2007 13:31:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:27685</guid><dc:creator>erik.peterson</dc:creator><slash:comments>3</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/products/rsscomments.aspx?PostID=27685</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/03/17/WebInspect-Update-now-Available.aspx#comments</comments><description>&lt;p&gt;Hot on the heels of our 7.0 release on Feb 14th, i&amp;#39;m happy to announce that our next WebInspect update release, version &lt;strong&gt;7.0.286.3&lt;/strong&gt;, is now available via SmartUpdate and download. This update delivers close to 250 issues and minor enhancements to the new WebInspect 7 platform. If you haven&amp;#39;t already downloaded it, please check it out now by hitting SmartUpdate.&lt;/p&gt;&lt;p&gt;We have also already started on the next update release as part of our new rapid release strategy, expect to see a steady stream of continuous updates throughout the year all made possible by our new Phoenix architecture. If you are looking for a new feature or have a particular annoyance you would love to see us address let us know by heading over to our &lt;a href="http://portal.spidynamics.com/forums/default.aspx?GroupID=14"&gt;WebInspect product forums&lt;/a&gt; and letting us know. For those of you who are customers and haven&amp;#39;t already done so, make sure you have activated your portal account for full customer access and to gain access to the product support forums as well by sending an e-mail to &lt;a href="mailto:portal@spidynamics.com"&gt;portal@spidynamics.com&lt;/a&gt;. &lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=27685" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=JKyqCMlz"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=uJ5wmvlM"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=uJ5wmvlM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/A5A8663RrzA" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/WebInspect/default.aspx">WebInspect</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/products/archive/tags/software+update/default.aspx">software update</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/products/archive/2007/03/17/WebInspect-Update-now-Available.aspx</feedburner:origLink></item></channel></rss>
